Networking
Network model and CNI
56 / 82

The flat network: any Pod can reach any other Pod directly, using real IPs.

Kubernetes states three rules and delegates the implementation to a CNI plugin chosen by your platform.

node-1 Pod CIDR 10.244.1.0/24node-2 Pod CIDR 10.244.2.0/24checkout10.244.1.5catalog10.244.1.6payments10.244.2.9same node: bridgecross-node, no NAT, source IP preservedCNI plugin builds this network
Rule 1

Every Pod gets its own unique IP address.

Rule 2

Every Pod can reach every other Pod's IP directly, without NAT, across nodes.

Rule 3

A Pod sees its own IP the same way others see it.

Common CNI plugins

Calico (routing, policy), Cilium (eBPF), Flannel (simple overlay), AWS VPC CNI (VPC IPs), Azure CNI, GKE Dataplane V2 (Cilium based).